196Articles
9Categories
2024-05-14Date
🚨
CISA Adds Google Chromium Vulnerability (CVE-2024-4671) to Known Exploited Vulnerabilities Catalogsubmitted by kid to cybersecurity 3 points | 0 comments https://www.cisa.gov/known-exploited-vulnerabilities-catalog
KEV
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-30051 Microsoft DWM Core Library Privilege Escalation Vulnerability CVE-2024-30040 Microsoft Windows MSHTML Platform Security Feature B…
KEV
πŸ›
Apple Patches Everything: macOS, iOS, iPadOS, watchOS, tvOS updated., (Tue, May 14th)
πŸ›
Another Chrome Vulnerability
πŸ›
Google Patches Second Chrome Zero-Day in One Week
πŸ›
Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code
πŸ›
Google Chrome Emergency Update Fixes Sixth Zero-Day Exploited in 2024
πŸ›
New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation
πŸ›
CVE-2024-32002 CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
πŸ›
CVE-2024-29996 Windows Common Log File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29997 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-29998 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-29999 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30000 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30001 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30002 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30003 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30004 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30005 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30006 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-30007 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30008 Windows DWM Core Library Information Disclosure Vulnerability
πŸ›
CVE-2024-30009 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30010 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2024-30011 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-30012 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30014 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30015 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30016 Windows Cryptographic Services Information Disclosure Vulnerability
πŸ›
CVE-2024-30017 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2024-30018 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30019 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2024-30020 Windows Cryptographic Services Remote Code Execution Vulnerability
πŸ›
CVE-2024-30021 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30022 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30023 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30044 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-30050 Windows Mark of the Web Security Feature Bypass Vulnerability
πŸ›
CVE-2024-30053 Azure Migrate Cross-Site Scripting Vulnerability
πŸ›
CVE-2024-30059 Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
πŸ›
CVE-2024-26238 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29994 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30024 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30025 Windows Common Log File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30027 NTFS Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30028 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30029 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30030 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30031 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30032 Windows DWM Core Library Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30033 Windows Search Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30034 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
πŸ›
CVE-2024-30035 Windows DWM Core Library Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30036 Windows Deployment Services Information Disclosure Vulnerability
πŸ›
CVE-2024-30037 Windows Common Log File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30038 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30039 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-30040 Windows MSHTML Platform Security Feature Bypass Vulnerability
πŸ›
CVE-2024-30041 Microsoft Bing Search Spoofing Vulnerability
πŸ›
CVE-2024-30042 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2024-30043 Microsoft SharePoint Server Information Disclosure Vulnerability
πŸ›
CVE-2024-30045 .NET and Visual Studio Remote Code Execution Vulnerability
πŸ›
CVE-2024-30046 Visual Studio Denial of Service Vulnerability
πŸ›
CVE-2024-30047 Dynamics 365 Customer Insights Spoofing Vulnerability
πŸ›
CVE-2024-30048 Dynamics 365 Customer Insights Spoofing Vulnerability
πŸ›
CVE-2024-30049 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30051 Windows DWM Core Library Elevation of Privilege Vulnerability
πŸ›
CVE-2024-32004 GitHub: CVE-2024-32004 Remote Code Execution while cloning special-crafted local repositories
πŸ›
CVE-2024-30054 Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability
πŸ›
Chromium: CVE-2024-4761 Out of bounds write in V8
πŸ›
FBI warns Black Basta ransomware impacted over 500 organizations worldwide
⚠️
Leveraging AI & The Role Identity Plays - BSW #350
⚠️
Low-tech tactics still top the IT security risk chart
⚠️
The role of law enforcement in remediating ransomware attacks
⚠️
Google Chrome emergency update fixes 6th zero-day exploited in 2024
⚠️
Apple iTunes for Windows Flaw Let Attackers Execute Malicious Code
⚠️
3 recommendations for adopting generative AI for cyber defense
⚠️
Black Basta ransomware group’s techniques evolve, as FBI issues new warning in wake of hospital attack
⚠️
CISA and Partners Release Guidance for Civil Society Organizations on Mitigating Cyber Threats with Limited Resources
⚠️
Ongoing Campaign Bombarded Enterprises with Spam Emails and Phone Calls
⚠️
Mallox Ransomware Deployed via MS-SQL Honeypot Attack
⚠️
Equipped with AI tools, hackers make apps riskier than ever
⚠️
New threat trends emerge out of East Asia
⚠️
VMware Patches Vulnerabilities Exploited at Pwn2Own 2024
⚠️
Mitigating cyber threats with limited resources: Guidance for civil society
⚠️
CISA Releases Four Industrial Control Systems Advisories
⚠️
CyberheistNews Vol 14 #20 Verizon: Nearly 80% of Data Breaches Involve Phishing and the Misuse of Credentials
⚠️
VMware fixes three zero-day bugs exploited at Pwn2Own 2024
⚠️
SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver
⚠️
NHS Digital Hints At Exploit Sightings Of Arcserve UDP Vulnerabilities
⚠️
VMware Patches Vulnerabilities Exploited At Pwn2Own 2024
⚠️
SAP Patches Critical Vulnerabilities In CX Commerce, NetWeaver
⚠️
Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own
⚠️
VMware Patches Severe Security Flaws in Workstation and Fusion Products
⚠️
Apple Releases Security Updates for Multiple Products
⚠️
INC Ransomware Source Code Selling on Hacking Forums for $300,000
⚠️
The Enterprise Browser & AI in Securing Software and Supply Chains - Mike Fey, Josh Lemos - ASW #285
⚠️
Inside the OWASP Top 10 for LLM Applications - Sandy Dunn - ASW #285
⚠️
Apple Backports Fix for Zero-Day Exploited in Attacks to Older iPhones
⚠️
Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
KEV
⚠️
Australian federal budget outlines investment in cybersecurity
⚠️
Threat intelligence to protect vulnerable communities
⚠️
Microsoft fixes Windows zero-day exploited in QakBot malware attacks
⚠️
Microsoft May 2024 Patch Tuesday, (Tue, May 14th)
⚠️
Attackers Leveraging XSS To Make Phishing Emails Increasingly Evasive
⚠️
NHS Digital Hints at Exploit Sightings of Arcserve UDP Vulnerabilities
⚠️
Microsoft Releases May 2024 Security Updates
⚠️
Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities
KEV
⚠️
Critical Patches Issued for Microsoft Products, May 14, 2024
⚠️
Patch Tuesday, May 2024 Edition
⚠️
Microsoft Patches Zero-Day Exploited by QakBot
KEV
⚠️
PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers
⚠️
RSA (β€œRSAI”) Conference 2024 Powered by AI with AI on Topβ€Šβ€”β€ŠAI Edition (Hey AI, Is This Enough AI?)
KEV
πŸ“‹
Microsoft fixes Windows Server bug causing crashes, NTLM auth failures
πŸ“‹
Microsoft fixes VPN failures caused by April Windows updates
πŸ“’
Sophos Incident Response achieves NCSC Certified Incident Response (CIR) Level 2 status
πŸ“’
Red Teaming: The Key Ingredient for Responsible AI
πŸ“’
Why Tokens are Like Gold for Opportunistic Threat Actors
πŸ“’
Canada joins international security partners in release of advisory, guidance on growing cyber security threat to civil society
πŸ“’
Cyber Insurers Pledge to Help Reduce Ransom Payments
πŸ“’
CISA, DHS, FBI and International Partners Publish Guide for Protecting High-Risk Communities
πŸ“’
Google Chrome security advisory (AV24-259)
πŸ“’
Apple security advisory (AV24-258)
πŸ“’
[Control systems] B&R security advisory (AV24-261)
πŸ“’
VMware security advisory (AV24-260)
πŸ“’
[Control systems] ABB security advisory (AV24-262)
πŸ“’
[Control systems] Siemens security advisory (AV24-263)
πŸ“’
SAP security advisory – May 2024 monthly rollup (AV24-265)
πŸ“’
Mozilla security advisory (AV24-264)
πŸ“’
Fortinet security advisory (AV24-267)
πŸ“’
Microsoft security advisory – May 2024 monthly rollup (AV24-266)
πŸ“’
Intel security advisory (AV24-269)
πŸ“’
Adobe security advisory (AV24-268)
πŸ”₯
In The Shadow Of Venus: Trinity Ransomware's Covert Ties
πŸ”₯
Hackers Abuse GoTo Meeting Tool to Deploy Remcos RAT
πŸ”₯
Zscaler Confirms Only Isolated Test Server Was Hacked
πŸ”₯
Threat Actor Selling INC Ransomware Code for $300,000
πŸ”₯
Hackers Abuse DNS Tunneling For Covert Communication & Firewall Bypass
πŸ”₯
Zscaler Concludes Investigation: Only Test Servers Compromised
πŸ”₯
Researchers Identify New Campaigns from Scattered Spider
πŸ”₯
New Botnet Sending Millions of Weaponized Emails with LockBit Black Ransomware
πŸ”₯
Student, Personnel Information Stolen in City of Helsinki Cyberattack
πŸ”₯
Cyber Insurers Pledge to Help Reduce Ransom Payments
πŸ”₯
Dell API abused to steal 49 million customer records in data breach | Cybersafe News Dell API abused to steal 49 million customer records in data breach
πŸ”₯
New Research: Number of Successful Ransomware Attacks Rise 29% in a Just One Year
πŸ”₯
Millions of Messages Distribute LockBit Black Ransomware
πŸ”₯
Christie's Art Auctions Hit By A Cyber Attack
πŸ”₯
Black Basta Ransomware Group Is Imperiling Critical Infrastructure
πŸ”₯
Zscaler Confirms Only Isolated Test Server Was Hacked
πŸ”₯
Ebury botnet malware infected 400,000 Linux servers since 2009
πŸ”₯
Threat actor scraped Dell support tickets, including customer phone numbers
πŸ”₯
Defending against popular cyberattack techniques in 2024
πŸ”₯
β€œUnknown” Initial Attack Vectors Continue to Grow and Plague Ransomware Attacks
πŸ”₯
Singing River Health System: Data of 895,000 stolen in ransomware attack
πŸ”₯
Impact of Ascension's Cyberattack IT Outage Varies by Region
πŸ”₯
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
πŸ•΅οΈ
MITRE Releases EMB3D Cybersecurity Threat Model for Embedded Devices
πŸ•΅οΈ
ISC Stormcast For Tuesday, May 14th, 2024 https://isc.sans.edu/podcastdetail/8980, (Tue, May 14th)
πŸ•΅οΈ
GPT-4o Released: Faster Model Available for Free to All Users
πŸ•΅οΈ
AI’s Rapid Growth Puts Pressure on CISOs to Adapt to New Security Risks
πŸ•΅οΈ
FCC Reveals Royal Tiger, its First Tagged Robocall Threat Actor
πŸ•΅οΈ
MITRE EMB3D Threat Model Officially Released
πŸ•΅οΈ
FCC Warns of β€˜Royal Tiger’ Robocall Scammers
πŸ•΅οΈ
Malicious Go Binary Delivered via Steganography in PyPI
πŸ•΅οΈ
Cyberthreat landscape permanently altered by Chinese operations, US officials say
πŸ•΅οΈ
Attackers Use DNS Tunneling to Track Victim Activity, Scan Networks
πŸ•΅οΈ
Alert: Nova Scotians Hit by Surge of Sophisticated Spear Phishing Scams
πŸ•΅οΈ
Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about
πŸ•΅οΈ
Hacker Conversations: Ron Reiter, and the Making of a Professional Hacker
πŸ•΅οΈ
That Data Sprawl is Here! What Should We Do About it? - Nick Ritter - CSP #174
πŸ•΅οΈ
Upcoming Speaking Engagements
πŸ•΅οΈ
AI Is An Expert Liar
πŸ•΅οΈ
Leveraging DNS Tunneling for Tracking and Scanning
πŸ•΅οΈ
Tornado Cash Developer Sentenced to 5 Years in Prison
πŸ•΅οΈ
Adobe Patches Critical Flaws in Reader, Acrobat
πŸ•΅οΈ
3000 Years Ago, Dell, Robocalls, PyPI, Cinterion, Cacti, Chat-GPT, Josh Marpet... - SWN #386
πŸ•΅οΈ
UK, US Officials Warn About Chinese Cyberthreat
πŸ•΅οΈ
ESET APT Activity Report Q4 2023–Q1 2024
🌐
Live Webinar | What’s Missing in Your Identity First Security Strategy?: Lessons from an ISMG Survey
🌐
Insider Threats Maintain a Rising Trend
🌐
Malicious PyPi Requests Fork Hides Backdoor In PNG File
πŸ“‘
Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices
πŸ“‘
Cybercriminals Steal One-Time Passcodes for SIM Swap Attacks and Raiding Bank Accounts
πŸ“‘
6 Mistakes Organizations Make When Deploying Advanced Authentication
πŸ“‘
The Future is Now: Tech Trends Driving App Devβ€”Gen AI, Low-Code and More
πŸ“‘
Southeast Asian Scam Syndicates Stealing $64 Billion Annually, Researchers Find
πŸ“‘
Live Webinar | Navigating the Intersection of IT Governance, AI & Modern App Development
πŸ“‘
Apple and Google add alerts for unknown Bluetooth trackers to iOS, Android
πŸ“‘
Google, Apple Gear To Raise Tracking Tag Stalker Alarm
πŸ“‘
$2.5 Million Offered Up At Matrix Cup Chinese Hacking Contest
πŸ“‘
Telegram CEO Calls Out Rival Signal, Claims It Has Ties With US Government
πŸ“‘
Apple touts stopping $1.8BN in App Store fraud last year in latest pitch to developers
πŸ“‘
Windows 11 KB5037771 update released with 30 fixes, changes
πŸ“‘
Vermont Passes Data Privacy Law Allowing Consumers to Sue Companies
πŸ“‘
Windows 10 KB5037768 update released with new features and 20 fixes
πŸ“‘
VMware makes Workstation Pro and Fusion Pro free for personal use